Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security vulnerability in this system could allow a high-privileged user to bypass file access restrictions by following malicious links. If exploited, this could lead to the unauthorized viewing of sensitive internal files, potentially compromising confidential business information.
Technical details
An improper link resolution (CWE-59) vulnerability exists in Dell PowerProtect Data Domain across multiple versions, including several Long Term Support (LTS) releases. The flaw occurs when the application fails to properly validate or resolve symbolic links before performing file operations. A remote attacker with high administrative privileges can exploit this by creating or manipulating links to point to files outside of the intended directory. Successful exploitation allows the attacker to read arbitrary files on the system, leading to unauthorized information disclosure. Dell has released security updates (DSA-2026-278) to address this issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory